Skip to content

SLEM 5 with Unified Extensible Firmware Interface (UEFI) implemented must require authentication upon booting into single-user mode and maintenance.

An XCCDF Rule

Description

If the system allows a user to boot into single-user or maintenance mode without authentication, any user that invokes single-user or maintenance mode is granted privileged access to all system information.

ID
SV-261268r996298_rule
Version
SLEM-05-212015
Severity
High
References
Updated

Remediation Templates

A Manual Procedure

Note: If the system does not use UEFI, this requirement is not applicable.

Configure SLEM 5 to encrypt the boot password.

Generate an encrypted GRUB bootloader password for root with the following command: